
CiscoCertified CyberOps Associate
Domain 3Objective 5
3.5 Interpret Operating System, SIEM, SOAR Platform, Application, or Command Line Logs to Identify an Event 200-201 Practice Questions (Page 4)
Part of the 3.0 Host-Based Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
20%of the exam
Questions 16–20
- 16
A database log shows multiple failed login attempts from the same user account followed by a successful login. Which type of event does this pattern most likely indicate?
Select an answer first - 17
A Windows analyst opens Event Viewer and sees Event ID 4624 with Logon Type 10 for a user account at 2:00 AM. The user is a standard employee who works 9–5. Which additional log field would most strongly confirm a malicious remote login rather than a local console login?
Select an answer first - 18
A Windows administrator is investigating a possible privilege escalation. The security log shows Event ID 4672 (special privileges assigned to new logon) for a standard user account. The administrator also sees Event ID 4688 (process creation) for 'cmd.exe' with a parent process of 'explorer.exe'. Which additional event should the administrator look for to confirm the privilege escalation?
Select an answer first - 19
A SOAR platform log shows that a playbook named 'Contain_Threat' executed a series of actions: it quarantined a file, blocked an IP address on the firewall, and created a ticket in the ticketing system. The log entry for the 'block IP' action shows a status of 'failed'. What is the most appropriate next step for the analyst?
Select an answer first - 20
In a SIEM, what is the primary purpose of a search query?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.